Decoding the world of cybersecurity

Industrial ransomware rises across most regions

Kaspersky telemetry shows ransomware detections rising across most industrial regions in Q2 2026 even as the overall share of ICS computers encountering malicious objects declined.

Industrial ransomware rises across most regions
Summary
  • Ransomware detections on ICS computers increased in most global regions during the second quarter.
  • Western Europe, Southern Europe and Canada were exceptions to the upward ransomware trend.
  • Overall malicious-object detections on industrial computers continued falling, reaching their lowest level since 2022.

Ransomware activity against industrial control system environments increased across most regions in the second quarter of 2026, even as the overall proportion of industrial computers encountering malicious objects continued to fall.

Kaspersky ICS CERT said its latest telemetry shows an increasingly uneven industrial threat picture: broad malicious activity is declining, while ransomware continues to push into environments where an IT outage can become an operational problem.

The percentage of ICS computers on which malicious objects of different types were blocked fell again during the quarter, reaching its lowest level since 2022. Ransomware moved in the opposite direction across most regions.

The largest quarter-on-quarter increases in ransomware detections were recorded in Australia and New Zealand, Southeast Asia, South America, Africa, Central Asia and the South Caucasus, and the Middle East. Western Europe, Southern Europe and Canada were the exceptions to the general rise.

Southern Europe nevertheless remained among the regions with comparatively high ransomware exposure in the dataset. That distinction is important: the region did not record an increase from the previous quarter, but its existing level still placed it among the more exposed areas in Kaspersky’s ranking.

The figures are based on detections from systems participating in Kaspersky’s telemetry and should not be read as a census of every industrial network. They measure the proportion of observed ICS computers on which particular malicious objects were blocked, rather than confirmed compromises or production outages.

Even with that limitation, the divergence between falling overall detections and rising ransomware is notable. Industrial cybersecurity programmes have spent years reducing indiscriminate malware exposure through segmentation, update processes and tighter control of removable media and internet access. Ransomware operators, meanwhile, have become increasingly reliant on legitimate administrative utilities and established remote-management mechanisms once they enter an environment.

That changes the operational challenge. Malware prevention at the perimeter can reduce one class of exposure, but an attacker using valid credentials, remote tools or compromised administrative systems may generate less obvious malicious traffic while still creating a path towards disruption.

Industrial environments also impose recovery constraints that differ from mainstream corporate IT. Rebuilding a user workstation or restoring a cloud application is not equivalent to restarting a control environment responsible for production equipment, building systems or physical processes. Availability, safety testing and vendor dependencies can all extend the consequences of a ransomware intrusion even where the encryption mechanism itself is familiar.

Kaspersky’s separate review of industrial incidents during the second quarter also recorded an increase in attacks associated with physical effects and operational interruption. Not every such incident involved ransomware, and the available reporting spans multiple threat categories, but the combination reinforces the distinction between cyber compromise in an office environment and compromise around systems linked to physical operations.

European organisations face a mixed regional picture. Western and Southern Europe did not follow the quarterly ransomware increase seen elsewhere, but the figures do not support treating the region as low risk. Southern Europe remains prominent in several industrial threat indicators, while the nature of ICS environments means a small number of successful incidents can carry far greater operational consequence than raw detection percentages suggest.

The Q2 data therefore points to a narrowing rather than disappearing industrial threat. Commodity malicious activity may be declining across the monitored population, but ransomware remains capable of cutting through that improvement and concentrating risk around systems where downtime is expensive and recovery is slow.

×